Unit 42 — Managed Detection & Response
Cortex Pro
Managed Detection & Response
Unit 42's elite threat hunters and analysts operating 24/7 inside your XDR environment. Full multi-vector coverage — endpoint, network, cloud, and identity — not just endpoint monitoring.
This is NOT a partner-delivered service. Cortex Pro is operated exclusively by Palo Alto Networks' Unit 42 team. Partners can recommend and facilitate the sale, but Palo Alto's own analysts manage all detection and response operations. Partners do not have access to the SOC operations workflow. Set expectations with customers accordingly — this is not a white-label or co-branded service that Optiv or other partners operate. The customer relationship for SOC operations is directly with Unit 42.
Overview
What is Cortex Pro (Unit 42 MDR)?
Cortex Pro is Palo Alto Networks' managed detection and response (MDR) service, delivered by Unit 42—PANW's elite threat intelligence and incident response arm. It is a service add-on that runs on top of Cortex XDR Pro per Endpoint. Customers must own XDR Pro to consume MDR.
Unit 42 analysts provide 24/7 monitoring, proactive threat hunting, and hands-on incident response using the full XDR telemetry stack. The service is enriched with Unit 42's proprietary threat intelligence derived from frontline IR engagements with hundreds of the world's largest organizations.
Service Scope
MDR Service Capabilities
What Unit 42 analysts do inside your environment — not just alerts, but active response.
Third-Party Validation
MITRE ATT&CK Managed Services Results
Independent MITRE evaluation of MDR detection coverage and speed — 2024 Managed Services evaluation.
Positioning Guide
When to Position MDR vs. DIY SOC
MDR isn't right for every customer. Use this framework to qualify when to lead with Cortex Pro vs. positioning XSIAM or co-managed options.
- Organization has 250–5,000 employees and no 24/7 SOC staff
- CISO needs to show board-level 24/7 coverage without budget for a full SOC build
- Customer has XDR Pro deployed and wants to maximize its value immediately
- Incumbent MDR provider is tool-agnostic and not natively integrated with their stack
- Customer recently experienced a breach and needs expert validation of posture
- Cyber insurance requires documented 24/7 monitoring and IR retainer
- Internal team is overwhelmed; analyst burnout is creating retention risk
- Large enterprise (5,000+ employees) with mature 24/7 SOC already staffed
- Customer wants to own their SOC but needs platform modernization
- Organization has strong SOAR/automation team and wants control over playbooks
- Existing SIEM contract renewal is the primary driver — focus on XSIAM migration
- Customer prefers Optiv-branded co-managed service (Optiv Tier 1 + Unit 42 Tier 2/3)
- Regulatory constraints require local data processing or in-house SOC staff
Optiv Opportunity
XMDR Partner Program
Palo Alto Networks offers the Cortex eXtended MDR (XMDR) specialization for NextWave partners who demonstrate expertise in delivering MDR services on top of the Cortex platform. CDW and other top PANW partners hold this designation.
MDR Co-Sell
Optiv co-sells Unit 42 MDR alongside XDR Pro deployments. Optiv handles deployment and integration; PANW handles SOC operations. Clean division of ownership.
MDR Displacement
Replace incumbent MDR providers (Arctic Wolf, Secureworks, ReliaQuest) in accounts where the customer uses or is migrating to Cortex XDR. Primary Optiv services opportunity.
IR Retainer Bundling
Bundle Unit 42 MDR with a PANW IR retainer for customers who want both continuous monitoring and guaranteed IR capacity. Addresses cyber insurance requirements in a single package.
Hybrid MDR Model
For customers wanting Optiv-branded service delivery: Optiv handles Tier 1 triage; Unit 42 handles Tier 2/3 hunting and response. Optiv retains the customer relationship and billing.
Commercial Structure
Pricing & Prerequisites
- Pricing model Per endpoint, per year add-on on top of XDR Pro. Custom quote; not publicly disclosed.
- Market range MDR market typically $10–30/asset/month ($120–360/yr). Unit 42 is positioned at the premium end given the IR pedigree and intelligence quality.
- Contract terms Multi-year commitments typically yield 15–25% discount. Minimum endpoint counts typically apply.
- AgentiX (5.0) AI pre-triages cases and enriches context before human analysts engage, reducing MTTR further in MDR deployments.
Sales Conversations
Discovery Questions
Questions to qualify MDR opportunities and build the Unit 42 business case.